AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap) — Threadlinqs Intelligence
As of 2026-07-28, AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap) is a high-severity malware threat attributed to Void Arachne (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 57 indicators of compromise.
Threat ID: TL-2026-1344 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-28 · revalidated 1× · latest source
Attribution: Void Arachne · China · ESPIONAGE
AhnLab ASEC documented AtlasRAT, a modular remote access trojan delivered through a four-stage, largely in-memory loader chain that begins with a Delphi executable disguised as "AGE Flash Player." The
AtlasRAT is a commercial-grade remote access trojan tracked by AhnLab ASEC in a report titled "Not Every Fox is Silver: Inside an AtlasRAT Loader Chain" (2026-07-15). The infection begins with a Delphi-compiled executable masquerading as an "AGE Flash Player" installer (Stage 1). This dropper decrypts and loads an embedded PE image (Stage 2) entirely in memory, which in turn reconstructs downloader shellcode from eight separately encrypted fragments (Stage 3). The shellcode reflectively maps and executes MainDll.dll, a 32-bit RAT payload, via a technique ASEC labels ServiceRun (Stage 4). No stage other than the initial dropper is written to disk, minimizing forensic artifacts and defeating static AV scanning of intermediate stages.
Once resident, AtlasRAT establishes command-and-control over TLS to 150.158.50.175:443, opening every session with an 8-byte handshake marker "BFuck\0\0\0" (hex 42 46 75 63 6b 00 00 00). The TLS session itself is wrapped in an additional application-layer ChaCha20 stream cipher, and the certificate presented is self-signed but spoofs the subject "CN=update.microsoft.com, O=Microsoft Corporation, C=US" (SHA-256 fingerprint 3f152103ea35c0f7feb205651a91e3c946b8057d1ea6f046ffc44fa611fd0267) to blend into HTTPS traffic logs and evade naive certificate-pinning defenses. ASEC's telemetry identified 43 active AtlasRAT C2 servers as of 2026-06-09, indicating an operationally mature, multi-tenant or affiliate-style infrastructure footprint consistent with a commercially distributed RAT rather than a single-operator tool.
The final-stage payload is built around a modular plugin architecture. Observed capabilities include offline/buffered keylogging (keystrokes cached locally and exfiltrated in batches rather than streamed live, reducing detectable network chatter), DLL injection into WeChat.exe to intercept or manipulate the popular Chinese messaging client, and a security-product inventory routine that fingerprints the presence of 33 distinct security executables on the host — behavior consistent with pre-attack reconnaissance intended to select an evasion profile or abort execution on well-defended hosts. General process/file enumeration and system information collection round out the plugin set. Persistence markers and configuration state are dropped to C:\Users\Public\Documents\ using the filenames offline.ini, MODIf.html, AtlasPro.ini, and Wxfun.dll, giving defenders concrete host-based indicators even though the loader chain itself is fileless.
ASEC's analysis explicitly compares AtlasRAT to previously reported "Silver Fox" activity. Silver Fox (also tracked as Void Arachne, SwimSnake, UTG-Q-1000, and "The Great Thief of Valley") is a Chinese-origin threat actor with a multi-year lineage running from Gh0st RAT derivatives through ValleyRAT, Gh0stCringe, HoldingHands RAT, and Winos 4.0 to the current "Atlas RAT" / AtlasCross family. Independent reporting (Hexastrike, The Hacker News, March 2026) documents a related Silver Fox campaign delivering an "Atlas RAT" via a triple-nested Setup Factory installer trojanizing a stolen Autodesk binary, dynamically resolving APIs via PEB walking, decrypting an embedded Gh0st RAT configuration, and downloading second-stage shellcode over raw TCP (port 9899) to a C2 domain bifa668[.]com (registered 2025-10-27, resolving to 61.111.250.139, ASN 138195 MOACK.Co.LTD, South Korea) fronted by nameservers a.share-dns.com/b.share-dns.net. That campaign's handshake, "SFuck\0\0\0" (hex 53 46 75 63 6b 00 00 00), differs from AtlasRAT's "BFuck" marker but the two samples share the distinct "By@V<" internal marker string, and both ultimately reflectively load a RAT DLL named/labeled as part of an "Atlas" family — the basis for ASEC's assessment of partial overlap without full identity. The related Silver Fox campaign used eleven brand-impersonating delivery domains (Zoom, Signal, Telegram, Surfshark VPN, Microsoft Teams, QuickQ VPN, UltraViewer, Trezor, KeFuBao, WangWang, plus on
Target sectors: consumer, technology, finance, government administration
Target regions: china, japan, malaysia, philippines, thailand, indonesia, singapore, india
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 57 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1195, T1195.002, T1059.001, T1204.002, T1053.005, T1620, T1055.001, T1562.001, T1562.006